skills/mukul975/anthropic-cybersecurity-skills/hunting-for-command-and-control-beaconing/Gen Agent Trust Hub
hunting-for-command-and-control-beaconing
Pass
Audited by Gen Agent Trust Hub on Apr 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [METADATA_POISONING]: There is an inconsistency in author attribution. The SKILL.md frontmatter lists the author as 'mahipal', while the LICENSE file specifies 'mukul975'.
- [INDIRECT_PROMPT_INJECTION]: The skill parses untrusted network telemetry (DNS, HTTP, and connection logs) which could contain adversarial strings intended to influence the AI agent. Ingestion points: log parsing functions in scripts/agent.py and scripts/process.py. Boundary markers: Absent; findings are reported without specific delimiters or instructions to ignore embedded content. Capability inventory: File system read access and report writing. Sanitization: Log data is extracted and reported without sanitization or escaping of potentially malicious strings.
Audit Metadata